Tracks

Here is the current (under construction) schedule for the tracks

By Tracks

MondayTuesdayWednesdayThursdayFriday
Chaos Engineering
GDPR
Keynotes
OWASP SAMM
Security Questions
Threat Model
CISO
DevSecOps
GDPR
Owasp Projects
OWASP SAMM
Security Questions
Threat Model
DevSecOps
GDPR
Owasp Projects
OWASP SAMM
Security Questions
Threat Model
CISO
DevSecOps
GDPR
Keynotes
Maps and Graphs
Owasp Projects
OWASP SAMM
Security Questions
Threat Model
Security Questions
Threat Model

By Sessions

Chaos Engineering

when dayMon
descriptionSessions focusing on Chaos Engineering
organizersRuss Miles Russ Miles


Total sessions for this track: 8

MondayTuesdayWednesdayThursdayFriday
PM-1
13:30 - 15:00
Creating a Steady-State Hypothesis
Pedley room
PM-2
15:30 - 16:30
Hands on Chaos Experiments
Pedley room
PM-3
16:30 - 17:30
Real world Chaos Engineering
Pedley room
Eve-1
19:30 - 21:00
Customising the Chaos Toolkit
Pedley room
Sessions not mapped to an day and time

(back to all track's schedule)

CISO

when dayTue,Thu
descriptionWorking Sessions on topics related for CISOs and C-Level execs.
organizersTony Richards Tony Richards


Total sessions for this track: 16

MondayTuesdayWednesdayThursdayFriday
DS-2
12:30 - 13:30
OWASP Collective Defence Cluster (CDC) - One year on
Table 3
Recruiting AppSec Talent
Table 1
PM-2
15:30 - 16:30
Cyber Insurance
Portland room
CISO Ask Me Anything (AMA)
PM-3
16:30 - 17:30
Cyber Risk Modeling
Portland room
DS-3
18:00 - 19:00
Vulnerability Intelligence Working Group
Table 3
Sessions not mapped to an day and time

(back to all track's schedule)

DevSecOps

when dayTue Wed Thu
descriptionSessions focusing on the DevSecOps tools and techniques to embed security as part of CI/CD pipelines
organizersImran Mohammed A Imran Mohammed A , Francois Raynaud Francois Raynaud


Total sessions for this track: 57

MondayTuesdayWednesdayThursdayFriday
AM-1
10:30 - 12:30
OWASP Defect Dojo
Maulden room
OWASP DevSecOps Studio
Maulden room
Integrating Security Tools in the SDL
Maulden room
WebAuthn - Getting started workshop
Maulden room
DS-2
12:30 - 13:30
Writing Akamai rules
PM-1
13:30 - 15:00
Integrating Security Tools in the SDL using OWASP DevSecOps Studio
Maulden room
Time slot over-subscribed
Agile Practices for Security Teams
Larch room
DevSecOps Maturity Model (DSOMM)
Maulden room
Creating Appsec metrics and visualisation
Maulden room
Time slot over-subscribed
From Threat Modeling to DevSecOps metrics
Maulden room
Writing security tests to confirm vulnerabilities and fixes
Pedley room
Create a Tech Radar for Security teams
PM-2
15:30 - 16:30
Owasp Cloud Security Workshop (BETA)
Maulden room
Time slot over-subscribed
secureCodeBox - How to improve your CI/CD pipeline with automated security tests
Pedley room
SOC Monitoring Visualisation
Maulden room
Time slot over-subscribed
Darktrace API & Elastic Stack
Securing the CI Pipeline
Maulden room
Using sumo logic to handle-incidents
PM-3
16:30 - 17:30
Time slot over-subscribed
Adding security to VSTS pipeline
313 - DevSecCon villa
Security Crowdsourcing
313 - DevSecCon villa
Using JIRA to create and execute Security Playbooks
Larch room
Integrating Security into an Spotify Model (and using Squads for Security teams)
Maulden room
Time slot over-subscribed
Web Application Honeypot
Portland room
DS-3
18:00 - 19:00
Share your playbooks and release them under Creative Commons
Table 4
Eve-1
19:30 - 21:00
Create a Slack bot in Python
313 - DevSecCon villa
Darktrace Tuning Session
317 - Photobox villa
Time slot over-subscribed
Darktrace Alerts
Integrate securityheaders.com in CI pipeline
https://os-summit.slack.com/messages/CAUTMJVS5
Eve-2
21:00 - 23:00
Time slot over-subscribed
Incident handling with DarkTrace
317 - Photobox villa
Writing Checkmarx SAST rules
313 - DevSecCon villa
Using Veracode SAST Engine
Sessions not mapped to an day and time

(back to all track's schedule)

GDPR

when dayMon,Tue,Wed,Thu
descriptionFrom GDPR Appropriate Security Controls to Real world GDPR practices, this is where the real GDPR security experts will be
organizersTony Richards Tony Richards , Dinis Cruz Dinis Cruz


Total sessions for this track: 26

MondayTuesdayWednesdayThursdayFriday
DS-2
12:30 - 13:30
Creating a standard for GDPR patterns
Table 2
DPO how to become one
Table 2
Meet the ICO
PM-1
13:30 - 15:00
Ask me anything (AMA) on GDPR
Hands-on GDPR Patterns
Portland room
PM-3
16:30 - 17:30
GDPR Appropriate Security Controls
Portland room
Using graphs for GDPR mappings and visualisations
DS-3
18:00 - 19:00
GDPR Compliance what does it mean?
Table 1
Time slot over-subscribed
European GDPR variations
Table 2
Share your security polices and release them under Creative Commons
Table 2
Time slot over-subscribed
DPO what to expect
Table 1
Gamification of GDPR compliance
Table 2
Eve-2
21:00 - 23:00
Using Threat Models for GDPR
317 - Photobox villa
Sessions not mapped to an day and time

(back to all track's schedule)

Keynotes

when dayMon,Thu
descriptionKeynote track featuring talks by security experts
organizers


Total sessions for this track: 15

MondayTuesdayWednesdayThursdayFriday
KN-2
9:40 - 9:55
Gamifying Security Dashboards
main-stage
Thinking in Graphs
main-stage
Crossing the river by feeling the stones
main-stage
Adding Privacy by Design in Secure Application Development
main-stage
DS-2
12:30 - 13:30
A seat at the table
main-stage
A long successful career in IT (women in tech)
main-stage
Informational Awareness
main-stage
InSecurity
main-stage
A shared understanding of Success
main-stage
Sessions not mapped to an day and time

(back to all track's schedule)

Maps and Graphs

when dayThu
descriptionWorking Sessions for CISOs
organizersDinis Cruz Dinis Cruz


Total sessions for this track: 21

MondayTuesdayWednesdayThursdayFriday
AM-1
10:30 - 12:30
Using maps to define how to capture, detect and prevent 6 real-world security incidents
Larch room
Using JIRA-NeoVis to graph Threat Models
Wardley Mapping – a practical session on how to use value chain mapping
Larch room
Using JIRA-NeoVis to create graphical representations of JIRA data
Larch room
DS-2
12:30 - 13:30
Creating ELK Dashboards
Table 1
Using Data Science for log analysis
Table 3
PM-1
13:30 - 15:00
Using User Story Mapping for effective communication
Larch room
Cell based Structures for Security
Larch room
PM-2
15:30 - 16:30
Create Wardley Maps for multiple security scenarios
Larch room
Using JIRA-NeoVis to graph GDPR Data Journeys
Larch room
SOC Value Chain using Wardley maps
Larch room
Sessions not mapped to an day and time

(back to all track's schedule)

Misc

when day
descriptionMisc Sessions on multiple topics
organizers


Total sessions for this track: 48

MondayTuesdayWednesdayThursdayFriday
AM-1
10:30 - 12:30
Time slot over-subscribed
OS Summit Website - how to use it
Pedley room
Summit Onboarding
Maulden room
Track Introductions
Larch room
Security Ethics Checklist
Montague room
Azure Security Features, Just a Few
Pedley room
Using Jira to handle Incident Response - simulations
PM-1
13:30 - 15:00
Hands-on JIRA Schema refactoring
Larch room
Time slot over-subscribed
Creating Open Source Avatao exercises
313 - DevSecCon villa
MSc Appication Security
Montague room
Ask me anything (AMA) - Meet the Experts
Time slot over-subscribed
Group Discussion on Learning from Digital Incidents
Pedley room
Using AI and ML for incident response
Larch room
PM-2
15:30 - 16:30
Lessons learned from public bug bounties programmes
314 - Owasp Projects villa
Time slot over-subscribed
JIRA Risk Workflow
Portland room
Squad Modelling and Cross Functional Teams
Pedley room
Women in Cyber-security: improving the gender balance
Montague room
PM-3
16:30 - 17:30
Diving into mobile cryptography using dynamic instrumentation with Frida
Villa-314
DS-3
18:00 - 19:00
Time slot over-subscribed
Hands-on JIRA Schema refactoring (DS)
main-stage
Job Fair
Table 4
Eve-1
19:30 - 21:00
Security Buttons Extended
313 - DevSecCon villa
Using press-releases as improved project's briefs
Sessions not mapped to an day and time

(back to all track's schedule)

Owasp Projects

when dayTue Wed Thu
descriptionSessions based around multiple Owasp Projects
organizers


Total sessions for this track: 13

MondayTuesdayWednesdayThursdayFriday
AM-1
10:30 - 12:30
Creation of Security Buttons
Pedley room
Application Security Verification Standard
314 - Owasp Projects villa
Juice Shop Coding Day
314 - Owasp Projects villa
Owasp Top 5 Machine Learning risks
Portland room
PM-1
13:30 - 15:00
Update MSTG with changes in Android 8 (Oreo)
314 - Owasp Projects villa
Testing iOS Apps without Jailbreak
314 - Owasp Projects villa
Time slot over-subscribed
Running CTF Games with OWASP Juice Shop
314 - Owasp Projects villa
PM-2
15:30 - 16:30
Update MSTG with changes in iOS 11
314 - Owasp Projects villa
Time slot over-subscribed
Owasp Testing Guide v5
314 - Owasp Projects villa
PM-3
16:30 - 17:30
Juice Shop Brainstorming
314 - Owasp Projects villa
Time slot over-subscribed
Eve-1
19:30 - 21:00
Zap - How to use it
314 - Owasp Projects villa
Reboot Owasp Books Project
314 - Owasp Projects villa
Sessions not mapped to an day and time

    (back to all track's schedule)

    OWASP SAMM

    when dayMon,Tue,Wed,Thu
    descriptionSAMM team working together in a 5-day sprint on SAMMv2
    organizersSebastien Deleersnyder Sebastien Deleersnyder , Bart De Win Bart De Win


    Total sessions for this track: 34

    MondayTuesdayWednesdayThursdayFriday
    AM-1
    10:30 - 12:30
    SAMMv2 working session - Governance
    311 - OWASP SAMM villa
    SAMMv2 working session - Operations
    311 - OWASP SAMM villa
    SAMM Project Meeting
    311 - OWASP SAMM villa
    PM-1
    13:30 - 15:00
    SAMM Introduction
    Portland room
    SAMMv2 working session - Design
    311 - OWASP SAMM villa
    SAMMv2 working session - Verification
    311 - OWASP SAMM villa
    Using the OWASP Maturity Model tool
    PM-2
    15:30 - 16:30
    SAMM - Best Practices
    Portland room
    SAMMv2 working session - Implementation
    311 - OWASP SAMM villa
    SAMMv2 Measurement Model
    311 - OWASP SAMM villa
    Creating an open 3rd Party Supplier Questionnaire and maturity model
    311 - OWASP SAMM villa
    PM-3
    16:30 - 17:30
    SAMM Round Table
    Portland room
    SAMMv2 Establish the Document Model
    311 - OWASP SAMM villa
    SAMM benchmarking
    311 - OWASP SAMM villa
    Eve-1
    19:30 - 21:00
    SAMM DevSecOps Version
    311 - OWASP SAMM villa
    Sessions not mapped to an day and time

    (back to all track's schedule)

    Security Questions

    when dayMon,Tue,Wed,Thu,Fri
    descriptionTrack focused on creating Security Questions and Answers (with daily quizzes planned for the evening sessions)
    organizersJohn Fitzgerald John Fitzgerald , Rachel Power Rachel Power


    Total sessions for this track: 50

    MondayTuesdayWednesdayThursdayFriday
    DS-1
    10:00 - 10:30
    Review quiz answers from Mon
    Table 6
    Review quiz answers from Tue
    Table 6
    Review quiz answers from Wed
    Table 6
    Review quiz answers from Thu
    Table 6
    AM-1
    10:30 - 12:30
    Security Questions workshop
    Montague room
    Create Docker Security Questions
    DS-2
    12:30 - 13:30
    Creating Security exams (How to)
    Table 5
    PM-1
    13:30 - 15:00
    Create PHP Security Questions
    Create Security Economics Quiz
    Montague room
    Consolidate and process all Security Quiz data
    Montague room
    PM-2
    15:30 - 16:30
    Create Owasp Top 10 Security Questions
    Montague room
    Create AWS Security Questions
    Montague room
    Create NodeJS Security Questions
    Montague room
    Create Owasp AWS Security Questions
    PM-3
    16:30 - 17:30
    Create .Net Security Questions
    Montague room
    Create Java Security Questions
    Montague room
    Create Perl Security Questions
    Montague room
    Prepare Thursday Quiz session
    Montague room
    Present Security Quiz Data
    Eve-1
    19:30 - 21:00
    Security Quiz Night (Mon)
    316 - CertDev villa
    Security Quiz Night (Tue)
    316 - CertDev villa
    Security Quiz Night (Wed)
    316 - CertDev villa
    Security Quiz Night (Thu)
    316 - CertDev villa
    Sessions not mapped to an day and time

    (back to all track's schedule)

    Threat Model

    when dayMon,Tue,Wed,Thu,Fri
    descriptionWith Working Sessions such as Attack chains as TM technique and Threat Model cheat sheets
    organizersSteven Wierckx Steven Wierckx


    Total sessions for this track: 53

    MondayTuesdayWednesdayThursdayFriday
    AM-1
    10:30 - 12:30
    Threat model cheat sheets
    Kings room
    Describe different ways of implementing TM in agile organisations
    Kings room
    IoT Threat Modeling Cheat Sheet
    Kings room
    Create generic TM for CMS
    Kings room
    PM-1
    13:30 - 15:00
    Threat model track opening session
    Kings room
    API Threat Modeling Cheat Sheet
    Kings room
    Docker and Kubernetes Threat Modeling Cheat Sheet
    Kings room
    Threat model guide
    Kings room
    Share your Threat Models diagrams and create a Book
    Kings room
    PM-2
    15:30 - 16:30
    Threat Modeling Website Structure
    Kings room
    Attack chains as TM technique
    Kings room
    How to Threat Model Features with Questionnaires
    Kings room
    How to scale Threat Modeling.
    Kings room
    PM-3
    16:30 - 17:30
    Update Treat Modeling website 1
    Kings room
    Back to the future with Threat Modeling
    Kings room
    Federated Login with Social Platforms Threat Modeling Cheat Sheet
    Kings room
    Threat Model training through Gamification
    Kings room
    Threat model closing session
    Kings room
    Eve-1
    19:30 - 21:00
    Using a Rules Engine and Risk Patterns with IriusRisk
    320 - Threat Modeling villa
    Update Treat Modeling website 3
    320 - Threat Modeling villa
    Update Treat Modeling website 4
    320 - Threat Modeling villa
    Update Treat Modeling website 5
    320 - Threat Modeling villa
    Eve-2
    21:00 - 23:00
    Update Treat Modeling website 2
    320 - Threat Modeling villa
    Sessions not mapped to an day and time

    (back to all track's schedule)